Dear TYPO3 Community,
with the release of TYPO3 14.3.0 LTS, a security fix has been included that is relevant for users who were running TYPO3 14.2.0. Users on older versions are not affected by this vulnerability.
Please review the corresponding security advisory and CVE record here:
https://typo3.org/security/advisory/typo3-core-sa-2026-005
https://www.cve.org/CVERecord
The advisory also contains information about manual actions required after updating, as updating to 14.3.0 LTS alone does not retroactively clean existing data.
If you have not yet updated to 14.3.0 LTS, please do so as soon as possible.
The packages can be downloaded here:
https://get.typo3.org
Best regards
Oliver Hader
--
Oliver Hader
TYPO3 .... inspiring people to share!
Get involved: https://typo3.community
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: Message signed with OpenPGP
URL: <http: lists.typo3.org pipermail typo3-announce attachments c144b35d attachment.pgp></http:>